Description
The Photo Gallery by Ays plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 6.4.8. This is due to missing nonce verification on the bulk action functionality in the 'process_bulk_action()' function. This makes it possible for unauthenticated attackers to perform bulk operations (delete, publish, or unpublish galleries) via a forged request granted they can trick an administrator into performing an action such as clicking on a link.
Problem types
CWE-352 Cross-Site Request Forgery (CSRF)
Product status
* (semver)
Timeline
| 2025-11-25: | Vendor Notified |
| 2025-12-01: | Disclosed |
Credits
Deadbee
References
www.wordfence.com/...-710d-4149-9a8d-aa84479f0980?source=cve
plugins.trac.wordpress.org/...y-photo-gallery-list-table.php
plugins.trac.wordpress.org/...y-photo-gallery-list-table.php
plugins.trac.wordpress.org/...y-photo-gallery-list-table.php